No hacker broke into Google’s database. The problem was how location data was collected, explained and retained.
Google has been fined €403 million by Ireland’s Data Protection Commission (DPC) following an investigation into the company’s processing of users’ location data.
The decision, announced on September 21, 2026, concerns Google’s handling of location information through features including Web & App Activity, Location History and Location Accuracy during the period from May 25, 2018, to February 4, 2020.
The case offers an important warning for African technology companies: data-protection problems do not always involve hackers.
A business can face regulatory action because users were not properly informed about how their personal information was being processed, because the legal basis for processing was inadequate, or because information was retained longer than necessary.
What happened to Google?
Ireland’s DPC, acting as the lead supervisory authority for Google in the EU, said its investigation found problems involving the lawfulness and fairness of Google’s processing, transparency and accountability obligations, as well as the retention of location data.
The regulator said users could have been unaware that their location information could be used, among other purposes, to influence advertising or infer interests.
The DPC imposed administrative fines totalling €403 million and ordered Google to bring the relevant processing into compliance within six months.
Google’s position, as described in the material surrounding the case, is that the investigation concerns older practices that have since been changed.
Why location information matters
Location data can reveal considerably more than a person’s geographical position.
Repeated location records may help establish:
- Where someone lives
- Where they work
- Their daily movements
- Places they regularly visit
- Religious or medical visits
- Meetings and events they attend
- People or places they frequently interact with
Even where a person’s name is not directly attached to the information, repeated location patterns can contribute to identifying an individual.
That makes location information particularly important for businesses that operate delivery, transportation, fintech, healthcare, social networking, advertising or e-commerce platforms.
A privacy violation is not necessarily a data breach
There is an important difference between the two.
A data breach generally involves unauthorised access, disclosure, loss or similar security incident involving personal information.
A data-protection violation, however, can occur because a company processes personal information unlawfully or fails to meet its obligations concerning transparency, purpose, retention or user rights.
That means a startup does not have to wait for hackers to become involved before taking privacy compliance seriously.
Five questions every startup should ask
1. What information are we collecting?
Create a clear inventory of personal information collected by your application, website, employees and third-party services.
Do not forget analytics platforms, advertising technology, payment processors and software development kits (SDKs).
2. Why do we need it?
Separate information that is essential to providing the service from information that is merely useful for marketing, analytics or future business plans.
If a piece of data is not necessary, consider whether collecting it creates unnecessary regulatory and security exposure.
3. Have we explained it clearly?
Privacy notices should be understandable to ordinary users.
People should be able to find out what information is collected, why it is collected, who may receive it and how long it will be retained.
4. Can users control their information?
Where consent is the legal basis for processing, users should be given a meaningful opportunity to provide and withdraw that consent.
A complicated process that makes it easy to accept tracking but difficult to reject it can create compliance concerns.
5. When will the information be deleted?
Every category of personal data should have a retention rationale.
Keeping information indefinitely simply because storage is cheap can create unnecessary risk.

The Nigerian connection
African startups should not assume that European data-protection rules are the only issue.
Nigeria has its own framework under the Nigeria Data Protection Act 2023, administered by the Nigeria Data Protection Commission (NDPC).
The Act provides for administrative sanctions. For a data controller or processor of major importance, the higher maximum amount can be the greater of ₦10 million or 2% of annual gross revenue from the preceding financial year. For organisations not classified as being of major importance, the standard maximum amount is the greater of ₦2 million or 2% of annual gross revenue.
The NDPC also states that data controllers must notify the Commission within 72 hours of becoming aware of a personal-data breach that is likely to result in a risk to individuals’ rights and freedoms.
What African founders should do now
A startup does not need a huge compliance department to begin improving its data practices.
Founders can start with a simple register showing:
- What personal data is collected
- Why it is collected
- Where it is stored
- Which employees or suppliers can access it
- Which third parties receive it
- The legal basis for processing
- How long it is retained
- When it will be deleted
- How users can exercise their rights
Companies should also review every SDK, analytics tool and advertising service connected to their applications.
The bigger lesson
The Google case demonstrates that privacy is not simply an IT problem.
It involves product design, marketing, legal compliance, cybersecurity and management decisions.
For African startups hoping to expand beyond their home markets, building privacy protections into a product from the beginning can reduce regulatory risk and make it easier to enter markets with stronger data-protection requirements.
The basic principle is straightforward:
Collect only what you need. Explain what you are doing. Give users meaningful control. Keep information only for as long as necessary.
That is a much cheaper strategy than discovering later that your data practices have become a regulatory problem.




















